> For the complete documentation index, see [llms.txt](https://sayonara.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sayonara.gitbook.io/writeups/ctf/tjctf-2023/web-outdated.md).

# web/outdated

### <mark style="color:blue;">Challenge Description</mark>

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FEJpNnULpUaPLZRyn3O5q%2Fimage.png?alt=media&amp;token=ff0fc46f-aca4-4acc-9bbe-5fc797a88bff" alt=""><figcaption></figcaption></figure></div>

### <mark style="color:blue;">Challenge Attachment</mark>

{% file src="/files/tTuci5N3UBczNkYXU8st" %}

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F4LrN3Dkli2izxOdyvwnV%2Fimage.png?alt=media&amp;token=67334870-8c28-40c4-971d-2237e80caf7f" alt=""><figcaption></figcaption></figure></div>

so this website takes a python code file from the user and executes it in the server using the command subprocess

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FUCD7mNYUnN3JHjwPEBfj%2Fimage.png?alt=media&amp;token=b13dbc6e-43cd-43d9-b0fb-4dac5efc93e3" alt=""><figcaption></figcaption></figure></div>

so to execute a python file we have to click on the upload button

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2Fnxo0mgDPCMBHXnI1PkbX%2Fimage.png?alt=media&amp;token=6bcda714-9aba-4798-b3b4-e99d0d344793" alt=""><figcaption></figcaption></figure></div>

before submitting any file intercept the submit request using burp and then send the request to repeater

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FZVbQ3aSs8fQ8Nfl8GiwO%2Fimage.png?alt=media&amp;token=d2e8e636-291b-4b7e-84e2-5c36d14ea66b" alt=""><figcaption></figcaption></figure></div>

i have created a simple python file that prints a string

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FnJKvqmXJ6DmrxcG9tDP7%2Fimage.png?alt=media&amp;token=79cbdc24-2780-4fa5-9959-6bcba8baaeec" alt=""><figcaption></figcaption></figure></div>

in the response it shows us the code and the resonse of the code executed

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FHRjPm5pu4Q2WqxNtvC5i%2Fimage.png?alt=media&amp;token=bc43e73c-c902-4853-8dfb-8c5758aea2b5" alt=""><figcaption></figcaption></figure></div>

so what we have to do now is try to locate the flag in the server and print it

after trying to list the files in the current directory it somehow blocks us

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FjGX02JBpNicMHBvFsa4y%2Fimage.png?alt=media&amp;token=0d0bf67b-7249-4d85-b9d0-2da3b3ae3563" alt=""><figcaption></figcaption></figure></div>

looking at the source code we find out that it's blocking a bunch of very important keywords that normally used to execute system commands

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FX6C95NmiyTJu8LXw1gsx%2Fimage.png?alt=media&amp;token=c1802a8c-105a-4743-97f4-e91cf19e207b" alt=""><figcaption></figcaption></figure></div>

so we have to escape them and try to find another way

1. List all classes which are running in this python system by using this command `print("".__class__.__mro__[1].__subclasses__())`

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FD2cdc9q0K37pjzkOEAqo%2Fimage.png?alt=media&amp;token=3cab4074-cbbf-403e-9aea-3e8a772044cb" alt=""><figcaption></figcaption></figure></div>

the response is not clear so right click on the response and then click on show response in browser and copy the link and paste it in the browser

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F3YQLag5Wx9BIiJtKcNWU%2Fimage.png?alt=media&amp;token=407bda94-93d0-40ab-9e51-7ee687e7a276" alt=""><figcaption></figcaption></figure></div>

so let's copy all the array and paste it in an editor so we can view them properly

2. Find the index of `<class 'os._wrap_close'>` in this case the index of `<class 'os._wrap_close'>` is 132

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F8bRK7YbiJuQOlrnIEsBa%2Fimage.png?alt=media&amp;token=1fe55e76-58e0-449f-a391-503d34c81871" alt=""><figcaption></figcaption></figure></div>

3. Call the system module in `__globals__` to list files and directories by using this command `"".__class__.__mro__[1].__subclasses__()[132].__init__.__globals__['s' + 'ys' + 'tem']('ls -la')`

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F2eEX905yjrtB1JtHuKcb%2Fimage.png?alt=media&amp;token=8032abaa-d305-49e4-9923-99d4ed1c8e54" alt=""><figcaption></figcaption></figure></div>

and we can see the flag so now let's use the command cat to read its content

4. Show the flag string from `flag.txt` by using this command `"".class.mro[1].subclasses()[132].init.globals['s' + 'ys' + 'tem']('cat flag-8f42541e-b457-42a3-8aae-a43d2d9782da.txt')`&#x20;

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FNVMgWBVhgaRJYnr93aLD%2Fimage.png?alt=media&amp;token=facf5268-e146-45b2-86f3-705b9250a94c" alt=""><figcaption></figcaption></figure></div>

### <mark style="color:blue;">Flag</mark>

```
tjctf{oops_bad_filter_3b582f74}
```
